The certificate must point on the hostname of the system, then it does not come to a hostname-missmatch. That's the purpose of a certficate, that it protects the mail server and the services.
Therefore, it must be issued to the host name of the system.
Let's Encrypt certificate with multiple...